lead-magnets

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions include a routine to read external marketing context from local project files, creating an ingestion surface for untrusted data.
  • Ingestion points: The skill attempts to read .agents/product-marketing.md, .claude/product-marketing.md, or product-marketing-context.md (found in SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potential commands embedded within these context files.
  • Capability inventory: The skill is designed for strategic planning and content outlining. No high-risk tools such as subprocess execution, network operations, or file-system modifications were detected in the provided skill code.
  • Sanitization: No sanitization or validation of the context file content is performed before ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:30 AM
Security Audit — agent-trust-hub — lead-magnets